Search NASASearch

SEARCH · Search NASA

Results for “Safety-related functionality”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

MARVEL Instrumentation, Control, and Software Considerations

This paper details the various I&C considerations and design decisions made throughout the MARVEL (Micro-reactor Applications Research Validation and Evaluation) project, including sensor and actuator selection, safety-related functionality, digital control hardware and software, and testing methodologies. Key challenges such as managing radiation, temperature, and space constraints are discussed, along with the trade-offs between using standard equipment and custom solutions. The successful integration of off-the-shelf components, the emphasis on minimizing safety-related instrumentation, and the lessons learned from prototyping and testing are highlighted. The authors aim to provide insights that can benefit future micro-reactor designs and emphasize the importance of real-world testing in advancing reactor technology.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN

Control System Upgrade for Battery State-of-Charge Indications

The Advanced Test Reactor (ATR) Complex at Idaho National Laboratory (INL) relies on Battery Backed Power (BBP) systems and Uninterruptible Power Supplies (UPS) to ensure continuous power supply to critical components. This project aims to enhance the reliability and functionality of the battery monitoring and control systems by updating the State-of-Charge (SOC) system, Programmable Logic Controller (PLC), and Human-Machine Interface (HMI) for the nuclear safety-related battery banks. The current system, while functional, has areas for improvement, particularly in recharging calculations and alarm functions. The project objectives include developing flow charts, programming the new PLC and HMI, conducting bench tests, and updating design documentation. Additionally, the project ensures compliance with safety standards, develops training materials, creates comprehensive documentation, and integrates seamlessly with existing ATR infrastructure. The new SOC system is designed to be scalable for future upgrades, improve efficiency, enhance data accuracy, implement redundancy features, and achieve project goals within budget constraints while considering environmental impact. The methodology involved familiarizing with BBP and UPS systems, collecting current readings, rescaling signals, learning ladder logic, and updating the HMI. The transition from SLC 5/03 PLC using RS Logix 500 to CompactLogix 5380 using Studio 5000 was a key step. Despite challenges in transferring outdated PLC ladder logic and HMI code, starting from scratch led to a more accurate and efficient monitoring system, contributing to improved safety and operational efficiency. The project is currently awaiting approval of the Engineering Calculation and Analysis Report (ECAR) before implementation.

42 - ENGINEERING

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS

Nuclear Data Impact Assessment for the HTR-10 Pebble-Bed Reactor Using SCALE

The HTR-10 was used as a representative pebble-bed high-temperature gas-cooled reactor in this assessment of nuclear data’s impact on important reactor and spent fuel metrics, including safety-related quantities such as the effective multiplication factor (k eff ), temperature reactivity feedback, spent fuel inventory, and decay heat. Using the SCALE code system tools and ENDF/B-VII.1 nuclear data libraries, we quantify the effect of nuclear data uncertainties on these key performance metrics for both fresh fuel and equilibrium core configurations. For reactor core key parameters, important contributors to uncertainty include reactions of 235 U [$\bar{v}$, fission, (n, γ)], 238 U [elastic, (n, γ)], and graphite [elastic, (n, γ)]. Additional important contributors for the equilibrium core include reactions of higher actinides ( 239 Pu, 240 Pu) and fission products ( 135 Xe, 149 Sm). For spent fuel analysis, most nuclide inventory uncertainties remain below 5%. Higher uncertainties up to 11% are being observed for minor actinides like 243 Am and 244 Cm. Additionally, fission product uncertainties in 155 Eu and 155 Gd, of 25% and 23% respectively, are also significant and have implications for burnup credit applications. 110m Ag also shows high uncertainty of up to 11%, mainly due to fission product yield uncertainties. Decay heat relative uncertainties remain below 0.6% up to 10 years’ cooling time after fuel discharge. The highest relative uncertainty of 1.5% occurs at 500 years of cooling; however, because the decay heat value is very low at that time, the absolute uncertainty is not significant. This work demonstrates that extending assessments beyond fresh fuel k eff to include irradiated cores, nuclide inventories, and decay heat is essential in understanding the behavior of uncertainties as a function of fuel burnup and can support improvements of safety margins and spent fuel management.

Nuclear data impact

Review of Reactor Facilities without Main Control Rooms

Small, advanced reactors may require few, if any, safety-related human actions (HAs) and fewer HAs to monitor and control the plant. In comparison to large light water reactors, these are significant changes that have implications for many aspects of an applicant's human factors engineering (HFE), including control room design, plant staffing, and the management of safety functions. To support the Nuclear Regulatory Commission's (NRC) ability to evaluate these changes, information needs to be developed addressing the characteristics and potential issues. The objectives of our research were to (1) identify when a traditional main control room (MCR) may not be necessary, (2) identify workplace design alternatives to traditional MCRs, and (3) develop guidance for reviewing an applicant's workplace designs with and without a MCR. We determined that the safety question isn't so much justifying why a design has no MCR, but rather verifying that important human actions can be accurately and reliably performed under a range of challenging conditions using the HSIs provided regardless of their location. We developed guidance to review alternatives to MCRs based on HFE analyses for determining workplace location and design.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Consideration of Decabromodiphenyl Ether Flame Retardant in Thermal and Radiation Aging of Crosslinked Polyethylene Cable Insulation

Decabromodiphenyl ether (decaBDE) has been used as a flame-retardant additive in nuclear-grade electrical cable insulation. However, decaBDE has been identified as a persistent, bioaccumulative and toxic (PBT) substance, leading to regulatory scrutiny. On January 6, 2021, the Environmental Protection Agency (EPA) published a final rule to phase out decaBDE. The 2021 rule set a two-year compliance deadline for “processing and distribution in commerce of decaBDE for use in wire and cable insulation in nuclear power generation facilities.” In recognition of industry concerns following a sudden discontinuation of decaBDE-containing Class 1E wire and cable essential for nuclear power operations and the time needed for qualifying the individual components using the alternative insulation technology, an extended compliance deadline was set in the finalized amendments to the 2021 rule as published by the Environmental Appeals Board on November 12, 2024. The 2024 rule set the compliance deadline for processing and distributing decaBDE-containing wire and cable insulation until the end of the service life of these materials. Since decaBDE has long been relied upon as the flame retardant in one of the most common cross-linked polyethylene (XLPE) nuclear cable insulation formulations, RSCC Firewall III insulation, questions have naturally arisen regarding whether changes in cable performance might be expected for XLPE containing a decaBDE alternative, especially for safety-related cables that must perform their safety function in a design basis event such as a loss of coolant accident.

22 GENERAL STUDIES OF NUCLEAR REACTORS